CVE-2005-2383 | PHPNews 1.2.5 auth.php User sql injection (EDB-26016 / Nessus ID 19287)
A vulnerability classified as critical has been found in PHPNews 1.2.5. Affected is an unknown function of the file auth.php. The manipulation of the argument User leads to sql injection.
This vulnerability is documented as CVE-2005-2383. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to upgrade the affected component.